CWE-287
Improper Authentication
Description
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-114 · CAPEC-115 · CAPEC-151 · CAPEC-194 · CAPEC-22 · CAPEC-57 · CAPEC-593 · CAPEC-633 · CAPEC-650 · CAPEC-94
CVEs mapped to this weakness (4,803)
page 14 of 241| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-50645 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2025 | MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token. | ||
| CVE-2024-50644 | Cri | 0.64 | 9.8 | 0.01 | Aug 22, 2025 | zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token. | ||
| CVE-2025-52395 | Cri | 0.64 | 9.8 | 0.01 | Aug 21, 2025 | An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails to validate the identity of the requester properly | ||
| CVE-2025-50901 | Cri | 0.64 | 9.8 | 0.00 | Aug 20, 2025 | JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading. | ||
| CVE-2024-50640 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2025 | jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function | ||
| CVE-2025-51451 | Cri | 0.64 | 9.8 | 0.00 | Aug 13, 2025 | In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm. | ||
| CVE-2025-45777 | Cri | 0.64 | 9.8 | 0.01 | Jul 25, 2025 | An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request. | ||
| CVE-2025-52376 | Cri | 0.64 | 9.8 | 0.10 | Jul 15, 2025 | An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server… | ||
| CVE-2025-7574 | Cri | 0.64 | 9.8 | 0.01 | Jul 14, 2025 | A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web Interface. The… | ||
| CVE-2025-49851 | Cri | 0.64 | 9.8 | 0.01 | Jun 24, 2025 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product. | ||
| CVE-2025-32877 | Cri | 0.64 | 9.8 | 0.01 | Jun 20, 2025 | An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authentication, which therefore allows… | ||
| CVE-2025-6172 | Cri | 0.64 | 9.8 | 0.00 | Jun 16, 2025 | Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation. | ||
| CVE-2025-37093 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2025 | An authentication bypass vulnerability exists in HPE StoreOnce Software. | ||
| CVE-2024-41198 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2025 | An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | ||
| CVE-2024-41197 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2025 | An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | ||
| CVE-2024-41196 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2025 | An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | ||
| CVE-2024-41195 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2025 | An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet. | ||
| CVE-2025-44083 | Cri | 0.64 | 9.8 | 0.01 | May 21, 2025 | An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication | ||
| CVE-2025-47889 | Cri | 0.64 | 9.8 | 0.01 | May 14, 2025 | In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames… | ||
| CVE-2023-44752 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2025 | An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php. |
- risk 0.64cvss 9.8epss 0.01
MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.
- risk 0.64cvss 9.8epss 0.01
zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.
- risk 0.64cvss 9.8epss 0.01
An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails to validate the identity of the requester properly
- risk 0.64cvss 9.8epss 0.00
JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.
- risk 0.64cvss 9.8epss 0.01
jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function
- risk 0.64cvss 9.8epss 0.00
In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.
- risk 0.64cvss 9.8epss 0.01
An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying a crafted request.
- risk 0.64cvss 9.8epss 0.10
An authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below, allowing an attacker to remotely enable the Telnet service without authentication, bypassing security controls. The Telnet server…
- risk 0.64cvss 9.8epss 0.01
A vulnerability, which was classified as critical, was found in LB-LINK BL-AC1900, BL-AC2100_AZ3, BL-AC3600, BL-AX1800, BL-AX5400P and BL-WR9000 up to 20250702. Affected is the function reboot/restore of the file /cgi-bin/lighttpd.cgi of the component Web Interface. The…
- risk 0.64cvss 9.8epss 0.01
ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities, which results in the use of the Just Works pairing method. This method does not implement any authentication, which therefore allows…
- risk 0.64cvss 9.8epss 0.00
Permission vulnerability in the mobile application (com.afmobi.boomplayer) may lead to the risk of unauthorized operation.
- risk 0.64cvss 9.8epss 0.01
An authentication bypass vulnerability exists in HPE StoreOnce Software.
- risk 0.64cvss 9.8epss 0.01
An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- risk 0.64cvss 9.8epss 0.01
An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- risk 0.64cvss 9.8epss 0.01
An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- risk 0.64cvss 9.8epss 0.01
An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.
- risk 0.64cvss 9.8epss 0.01
An issue in D-Link DI-8100 16.07.26A1 allows a remote attacker to bypass administrator login authentication
- risk 0.64cvss 9.8epss 0.01
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames…
- risk 0.64cvss 9.8epss 0.01
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.